Free Newsletter
Register for our Free Newsletters
Access Control
Deutsche Zone (German Zone)
Education, Training and Professional Services
Government Programmes
Guarding, Equipment and Enforcement
Industrial Computing Security
IT Security
Physical Security
View All
Other Carouselweb publications
Carousel Web
Defense File
New Materials
Pro Health Zone
Pro Manufacturing Zone
Pro Security Zone
Web Lec

Four layered defence against DNS vulnerability

Nominum : 01 September, 2008  (New Product)
In-depth security against DNS cache poisoning from Vantio software delivering four layers of integrated defence
Nominum has announced the availability of a comprehensive new security release for its Vantio caching DNS server platform. The latest Vantio software release provides multi-layer intelligent defences that defeat DNS cache poisoning and other attacks, including the recently publicized Kaminsky vulnerability. By offering built-in defence-in-depth, the Nominum solution far surpasses the recently released industry standard UDP Source Port Randomisation (UDP SPR). In fact, Vantio's new defences negate the brute force advantage attackers gained with the latest DNS cache poisoning vulnerability.

"Literally one day after details of the Kaminsky cache poisoning attack were revealed, UDP Source Port Randomisation was defeated in 10 hours by security researchers using brute-force spoofed responses," said Dr Paul Mockapetris, Chairman and Chief Scientist at Nominum and inventor of the DNS. "Nominum's multi-layered approach eliminates the risk of a successful attack."

Key benefits of new Vantio DNS security features:.

* Resists and stops all forms of cache poisoning attacks.
* Defends automatically against query response spoofing and takes attackers out of loop.
* Prevents hijacking of subscriber traffic, or "pharming" attacks.
* Identifies perpetrators and records attack attempts.
* Provides protection in Enterprise and Service Provider networks that use network address translation (NAT), which can undermine UDP SPR (NAT devices include server load balancers and firewalls).
* Reduces the chance of poisoning answers for valuable domains ( to zero.

Nominum and its customers were instrumental in implementing and deploying UDP SPR as part of an industry-wide response to the cache poisoning threat. This feature offered immediate protection to over 120 million broadband subscribers supported by Nominum DNS servers at nearly one hundred carriers and ISPs (click here for a partial list of Nominum's key customers).

UDP source port randomisation is only a first-step response to the new vulnerability, and network operators need additional deterministic defences to address important exploits. Cache poisoning attacks rely on many techniques, and response spoofing is only one of them. UDP source port randomisation is designed to mitigate risk of spoofing, but is not effective against a determined attacker or other forms of attacks. Response spoofing can be easily subverted when more network resources are available to an attacker that allow for sending many spoofed responses. Nominum's new defences are critical to ensuring the attacker does not succeed.

'Layered defences in the DNS system are an effective way to address serious attack scenarios that aren't covered by UDP Source Port Randomisation alone,' said Dan Kaminsky, the security researcher who discovered the latest DNS vulnerability. 'As new DNS vulnerabilities are discovered, a layered approach such as Nominum's will help in ensuring ongoing Internet security.'

Vantio features the following four security layers with key security features highlighted:.

* Deterrence Layer: Includes Nominum's leading UDP Source Port Randomisation implementation, the recommended industry response to the Kaminsky threat.
* Defence Layer: Incorporates Nominum's "Detect and Defend" capability to detect spoofing attempts and automatically switch the resolution to a secure connection in response to an attack attempt.
* Resistance Layer: Employs Query Response Screening with a set of features that intelligently screen DNS answers to ensure malicious data in DNS responses is not used to answer valid user queries.
* Remediation Layer: Sends alerts when an attack is under way and incorporates a new feature that records the attack, allowing the attacker to be identified, and real-time remedial action to be taken by the network operator.

"Layered security is the only way to defend against the emerging threats to the Internet," said Tom Tovar, CEO of Nominum. "Our customers, the largest networks in the world, have an obligation to deliver the highest-level of security in delivering Internet service to consumer, enterprise and government users. Nominum's new software release ensures that our customers can meet that obligation immediately and completely."

The new Vantio release is generally available as standard software purchase for carriers, large enterprise and government customers.
Bookmark and Share
Home I Editor's Blog I News by Zone I News by Date I News by Category I Special Reports I Directory I Events I Advertise I Submit Your News I About Us I Guides
   © 2012
Netgains Logo